<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: pratikshap31</title>
    <description>The latest articles on DEV Community by pratikshap31 (@pratikshap31).</description>
    <link>https://dev.to/pratikshap31</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F898161%2F8caa7d1c-fd09-41ed-983e-6d3b7480af32.png</url>
      <title>DEV Community: pratikshap31</title>
      <link>https://dev.to/pratikshap31</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/pratikshap31"/>
    <language>en</language>
    <item>
      <title>I am getting session cookies domain error while running the enlighten package.</title>
      <dc:creator>pratikshap31</dc:creator>
      <pubDate>Fri, 29 Jul 2022 08:36:15 +0000</pubDate>
      <link>https://dev.to/pratikshap31/i-am-getting-session-cookies-domain-error-while-running-the-enlighten-package-1m27</link>
      <guid>https://dev.to/pratikshap31/i-am-getting-session-cookies-domain-error-while-running-the-enlighten-package-1m27</guid>
      <description>&lt;p&gt;Check 92/126: Horizon uses a separate sub-domain with its own set of cookies to protect against session hijacking. Failed While Horizon uses a separate domain, your application session cookies are still shared with Horizon. This exposes your application to session hijacking, where if either your main application or Horizon is compromised, the other would also be compromised. It is recommended to configure separate cookies by setting the session domain configuration to null. At config/session.php, line 158. Documentation URL: &lt;a href="https://www.laravel-enlightn.com/docs/security/horizon-security-analyzer.html"&gt;https://www.laravel-enlightn.com/docs/security/horizon-security-analyzer.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I have multiple subdomains. each user has their own subdomain. I have the primary subdomain “my”. I am using session_domain to manage session cookies. The value of the session domain is “.projectame.com”. I am facing a redirect issue when putting a null value for session_domain.&lt;/p&gt;

&lt;p&gt;when the session domain is null, I am having an issue redirecting from my.projectname.com to username.projectname.com.&lt;/p&gt;

&lt;p&gt;Does anyone know how to solve it?&lt;/p&gt;

</description>
      <category>laravel</category>
      <category>horizon</category>
      <category>session</category>
      <category>cookie</category>
    </item>
    <item>
      <title>Session hijacking issue in laravel enlightn</title>
      <dc:creator>pratikshap31</dc:creator>
      <pubDate>Tue, 26 Jul 2022 08:40:07 +0000</pubDate>
      <link>https://dev.to/pratikshap31/session-hijacking-issue-in-laravel-enlightn-1ml6</link>
      <guid>https://dev.to/pratikshap31/session-hijacking-issue-in-laravel-enlightn-1ml6</guid>
      <description>&lt;div class="ltag__stackexchange--container"&gt;
  &lt;div class="ltag__stackexchange--title-container"&gt;
    
      &lt;div class="ltag__stackexchange--title"&gt;
        &lt;div class="ltag__stackexchange--header"&gt;
          &lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--7Gn-iPj_--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev.to/assets/stackoverflow-logo-b42691ae545e4810b105ee957979a853a696085e67e43ee14c5699cf3e890fb4.svg" alt=""&gt;
          &lt;a href="https://stackoverflow.com/questions/73119438/session-hijacking-issue-in-laravel-enlightn" rel="noopener noreferrer"&gt;
            Session hijacking issue in laravel enlightn
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="ltag__stackexchange--post-metadata"&gt;
          &lt;span&gt;Jul 26 '22&lt;/span&gt;
            &lt;span&gt;Comments: 1&lt;/span&gt;
            &lt;span&gt;Answers: 0&lt;/span&gt;
        &lt;/div&gt;
      &lt;/div&gt;
      &lt;a class="ltag__stackexchange--score-container" href="https://stackoverflow.com/questions/73119438/session-hijacking-issue-in-laravel-enlightn" rel="noopener noreferrer"&gt;
        &lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--Y9mJpuJP--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev.to/assets/stackexchange-arrow-up-eff2e2849e67d156181d258e38802c0b57fa011f74164a7f97675ca3b6ab756b.svg" alt=""&gt;
        &lt;div class="ltag__stackexchange--score-number"&gt;
          0
        &lt;/div&gt;
        &lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--wif5Zq3z--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev.to/assets/stackexchange-arrow-down-4349fac0dd932d284fab7e4dd9846f19a3710558efde0d2dfd05897f3eeb9aba.svg" alt=""&gt;
      &lt;/a&gt;
    
  &lt;/div&gt;
  &lt;div class="ltag__stackexchange--body"&gt;
    
&lt;p&gt;I am getting session cookies domain error while running the enlightn package.&lt;/p&gt;
&lt;p&gt;Check 92/126: Horizon uses a separate sub-domain with its own set of cookies to protect against session hijacking. Failed
While Horizon is currently using a separate domain, your application session cookies are still shared with Horizon. This exposes…&lt;/p&gt;
    
  &lt;/div&gt;
  &lt;div class="ltag__stackexchange--btn--container"&gt;
    &lt;a href="https://stackoverflow.com/questions/73119438/session-hijacking-issue-in-laravel-enlightn" class="ltag__stackexchange--btn" rel="noopener noreferrer"&gt;Open Full Question&lt;/a&gt;
  &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>laravel</category>
      <category>php</category>
      <category>security</category>
    </item>
  </channel>
</rss>
